Talent.com
Thumbtack
Staff Application Security EngineerThumbtack • Winnipeg, Canada
Staff Application Security Engineer

Staff Application Security Engineer

Thumbtack • Winnipeg, Canada
3 days ago
Salary
CA$221,000.00 yearly
Job type
  • Full-time
Job description
About the Cybersecurity Team The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start.

We partner closely with Product, Engineering, Platform, and Data teams to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust.

Challenge As Thumbtack scales and increasingly incorporates AI‑powered features into our products and internal systems, security must evolve without slowing innovation. The number of services, deployment patterns, and data flows continues to grow, and traditional approaches that rely heavily on manual reviews or after‑the‑fact controls do not scale to meet this need.

Instead, the challenge is to design security into the system itself. This means building secure defaults, paved paths, and reusable building blocks that product and engineering teams can adopt with minimal friction. By embedding security directly into architectures, tooling, and infrastructure, we reduce cognitive load on engineers and enable teams to move quickly and confidently while meaningfully lowering risk.

What You’ll Do

Own the long‑term technical direction for application security across Thumbtack. Build prioritized roadmaps and drive remediation of systemic security risks across the application stack.

Lead large, cross‑functional security initiatives from problem definition through delivery.

Design secure‑by‑default architectures, standards, and paved paths for engineering teams. Design and implement shared security tooling, libraries, patterns, and services that enable engineering to ship quickly and safely. Embed security into CI/CD pipelines, cloud infrastructure, and developer workflows.

Partner with engineering and product leaders to prioritize security investments based on risk, impact, and business goals.

Lead application security design reviews, architectural discussions, and threat modeling for critical systems. Contribute code, reviews, and designs to address complex or novel security risks.

Mentor engineers and raise the overall security bar through guidance and example.

Support security incident response and drive learning through post‑incident analysis.

In order to be successful, you must bring

8+ years of experience in software engineering and application security, including a strong understanding of secure coding practices and application security frameworks.

Deep expertise in secure system design and architecture as well as modern application security tools, patterns, and practices (e.g., threat modeling, secure design patterns, authentication and authorization, secrets management, vulnerability discovery and remediation workflows).

Proven track record leading large, cross‑functional technical initiatives with sustained impact.

Strong experience securing modern, cloud‑native systems (AWS and/or GCP).

Strong product intuition and analytical, risk‑informed thinking, identifying where security investments will have the highest leverage and measurable impact. Ability to balance pragmatism and rigor, making thoughtful tradeoffs between risk, velocity, and maintainability.

Strong sense of ownership and accountability, balancing hands‑on technical execution with the ability to mentor others, raise standards, and drive organization‑wide improvements in application security.

Excellent written and verbal communication skills, with the ability to influence without authority and the ability to explain complex security issues to both technical and non‑technical audiences.

Expected salary ranges

For candidates living in Ontario and British Columbia, the expected salary range for the role is currently $221,000.00 - $286,000.00.

Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role.

Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law.

Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact recruitingops@thumbtack.com.

If you are a California resident, please review information regarding your rights under California privacy laws contained in Thumbtack’s Privacy policy available at https://www.thumbtack.com/privacy/.

#J-18808-Ljbffr
Create a job alert for this search

Staff Application Security Engineer • Winnipeg, Canada

Similar jobs

Staff Product Security Engineer

AffirmWinnipeg, MB, CA
Full-time

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.Affirm values information... Show more

 • Promoted

Staff Engineer - Application Security at UniUni

UniUniWinnipeg, Manitoba, Canada
Full-time

Be the cornerstone of application security at UniUni as a Staff Engineer.Engage with engineering teams to establish security protocols for our innovative cloud-native solutions, working remotely.As... Show more

 • Promoted • New!

Application Security Engineer

PaxosWinnipeg, Canada
Full-time

About PaxosToday’s financial infrastructure is archaic, expensive, inefficient and risky — supporting a system that leaves out more people than it lets in.We’re on a mission to open the world’s fin... Show more

 • Promoted

Application Security Engineer Expert

DayforceWinnipeg, Canada
Full-time

Elevate your impact as an Application Security Engineer Expert, focusing on secure application design and robust security assessments.Lead integrations of security best practices across engineering... Show more

 • Promoted

Healthcare Ai Security Engineer

People MachineWinnipeg, Canada
Full-time

Lead security architecture efforts as a Senior Security Engineer in a fast-evolving healthcare AI startup.Focus on Azure security, compliance management, and operational excellence in security prac... Show more

 • Promoted

Application Security Engineer

DataAnnotationWinnipeg, Canada
Full-time +1

We are looking for experienced cybersecurity professionals to join our team to help train AI models.In this role, you will evaluate AI-generated security content, solve technical cybersecurity prob... Show more

 • Promoted

Security Engineer

Lawrence HarveyWinnipeg, Canada
Full-time

Lawrence Harvey is partnered with a SaaS company that's growing in the semiconductor space.Their security team is growing and we’re looking for a hands-on Security Engineer to help shape and sc... Show more

 • Promoted

Staff Software Engineer - Security & Privacy

SamsaraWinnipeg, Canada
Full-time

Who we are Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (Io... Show more

 • Promoted

Senior Hardware Security Engineer

LimeWinnipeg, Canada
Full-time

Lime is the largest global shared micromobility business, operating in close to 30 countries across five continents.We’re on a mission to build a future where transportation is shared, affordable a... Show more

 • Promoted

Security Operations Engineer

Jane AppWinnipeg, Canada
Full-time

About The Role Hi, I'm Dave Dowe, Senior Manager of Security Engineering at Jane.I've been here for two years, and I lead the team that keeps our platform secure - from incident response to... Show more

 • Promoted

Staff Application Security Engineer

UniUniWinnipeg, Canada
Full-time

UniUni is a late-stage last-mile logistics company moving millions of parcels across the United States and Canada for some of the largest e-commerce platforms in North America.Our technology is clo... Show more

 • Promoted

Blockchain Security Engineer - Application Focus

PaxosWinnipeg, Canada
Full-time

Elevate financial security as an Application Security Engineer with a focus on blockchain technology.Your role will involve ensuring code security and streamlining development through tailored secu... Show more

 • Promoted

Staff Security Engineer

LiveKitWinnipeg, Canada
Full-time

LiveKit is building the infrastructure layer for the voice‑driven era of computing.Our platform gives developers everything they need to build, test, deploy, scale, and observe agents in production... Show more

 • Promoted

Security Engineer Ii - Ops Team At Instacart

InstacartWinnipeg, Canada
Full-time

Become a crucial part of Instacart’s CAPS team as a Senior Security Engineer II.This remote role encompasses risk identification, system development, and mentoring engineering teams.You will work c... Show more

 • Promoted

Staff Product Security Engineer New

ChainguardWinnipeg, Manitoba, Canada
Full-time

Chainguard is the trusted source for open source.By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organi... Show more

 • Promoted

Security Engineer (Sentinel / SIEM)

JobgetherWinnipeg, Manitoba, Canada
Full-time

This position is posted by Jobgether on behalf of a partner company.We are currently looking for a Security Engineer (Sentinel / SIEM) in Canada.In this role, you will support a critical federal-fa... Show more

 • Promoted

Hands-On Security Engineer Role

Lawrence HarveyWinnipeg, Manitoba, Canada
Full-time

Drive security initiatives in a dynamic SaaS company as a Security Engineer.Focus on cloud security and enhance developer safety in a modern environment.The Security Engineer will be instrumental i... Show more

 • Promoted

Web Application Security Expert Role

Aha!Winnipeg, Canada
Full-time

Take the next step as a Web Application Security Expert with Aha!, the top product development software platform.Drive security innovations while working with remote, talented teams.As a Senior Sec... Show more

 • Promoted • New!

Application Security Engineer – Breaker & Builder

PaxosWinnipeg, Canada
Full-time

A leading fintech startup in Canada is seeking an Application Security Engineer to ensure security in financial and blockchain ecosystems.This role involves deep-dive security testing and developin... Show more

 • Promoted

Ai-Focused Application Security Engineer For Cyber Threat Analysis

DataAnnotationWinnipeg, Canada
Full-time

Advance your cybersecurity career by training AI models that combat real-world threats.Collaborate remotely to evaluate AI security outputs, troubleshoot technical issues, and enhance cybersecurity... Show more